cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
919
Views
0
Helpful
2
Replies

Cisco ISE dot1x & Active Directory Authentication

Nick Mavrou
Level 1
Level 1

Hi team,

I have a quick question regarding the AD authentication and the way how ISE does authenticate users from AD. So far I see, it is based on AD groups. Is it a way to set up a policy/condition for a specific user in a group instead of allowing all the users of the specified group to authenticate? 

 

Many thanks

1 Accepted Solution

Accepted Solutions

@Nick Mavrou you authenticate to an identity store (AD/LDAP etc), you then have to authorise, which is generally an AD group or if required you can define a specific AD username. In the authorisation rule you can use the condition "Network Access Username EQUALS <username>"

View solution in original post

2 Replies 2

@Nick Mavrou you authenticate to an identity store (AD/LDAP etc), you then have to authorise, which is generally an AD group or if required you can define a specific AD username. In the authorisation rule you can use the condition "Network Access Username EQUALS <username>"

@Rob Ingram Sweet thank you very much sir. Much appreciate!

NM